Skip to main content
Praxikon

Free template · Excel · English and Dutch

Shadow AI checklist and AI system inventory template (free Excel)

A shadow AI scan is a structured inventory of the AI tools staff use, including unapproved ones such as a chat assistant on a personal account or an AI feature switched on in existing software. It starts with sources that do not monitor employees and records a priority and a decision per tool, as the basis for the AI register.

Last checked against the law
Editor
, jurist, privacy and AI
Version and template ID
2.0 · praxikon:template:ai-gebruiksscan
Legal basis
Art. 3, 4, 5, 16, 25, 26, 50 and 111 and Annex III of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744; Art. 5, 6, 9, 13, 21, 22, 25, 28, 30, 32 to 36 and 44 et seq. GDPR; Art. 88 GDPR and national law on works councils (in the Netherlands: Works Councils Act (WOR), art. 27(1)(e), (k) and (l))

Who is this template for?

  • AI coordinator or compliance officer running the scanRole per application (Article 3(3) and (4)) and AI literacy measures (Article 4)
  • Data protection officer or privacy leadLegal basis, DPIA and prior consultation (Articles 6, 35 and 36 GDPR)
  • IT and information securityTechnical sources only after the privacy gate; data minimisation and security (Articles 5(1)(c), 25 and 32 GDPR)
  • HR and recruitmentAI in recruitment and appraisal (Annex III, point 4) and the shift to the provider role (Article 25(1)(c))
  • Works council or other employee representativesConsent or consultation on tools that can monitor staff, under national law (Article 88 GDPR; in the Netherlands, Works Councils Act, art. 27(1)(l))
  • Procurement and financeContracts, expense claims and data processing agreements (Article 28 GDPR)

What is inside

  • An overview that counts for you: progress, priorities, open decisions and the status of the privacy gate (Overview sheet)
  • A two-step approach: eight sources that do not monitor staff, four technical sources only after the privacy gate, and three things you do not do (Approach sheet)
  • Five texts to copy: announcement, survey introduction, reporting point, notice for a technical source and feedback (Notices sheet)
  • An anonymous staff survey with thirteen questions, each linked to a column of the findings (Survey sheet)
  • An interview guide with eleven questions per department and a log of which departments you have interviewed (Interview guide and Departments sheets)
  • Findings for 100 tools with a calculated priority, signals for Article 5, Article 50 and Annex III, a decision and the hand-over to the AI register (Findings sheet)
  • A privacy gate with fourteen conditions from the GDPR, the AI Act and works council law (Privacy gate sheet)
  • Six fictional examples that show how to fill it in

How to use the template

  1. On the Approach sheet, give each source an owner and a date, and complete all step 1 sources first: procurement, expense claims, connected apps, AI features in existing software and existing records.
  2. Inform the works council or other employee representatives as your national law requires, announce the scan with the texts on the Notices sheet and open the reporting point.
  3. Send out the survey and hold a 30 to 45 minute interview with every department.
  4. Enter every tool found on the Findings sheet, one row per tool and not per employee, and take a decision per row: allow, allow with conditions, replace or stop.
  5. Still want to use a technical source afterwards? Complete the privacy gate first and only start when the Overview shows 'May start'.
  6. Add every allowed application to your AI register and use the outcome for your AI policy and AI literacy measures. Repeat the scan every six months.

Common mistakes

  • Starting with network monitoring or a detection tool. That is personal data of employees: as controller you need a legal basis, as a rule a DPIA, the involvement of employee representatives that national law requires and prior information to staff. Sources that do not monitor anyone find the most in practice.
  • Relying on employee consent. Given their dependent position it is rarely freely given; a private employer records a legitimate interests assessment, a public authority its public task.
  • Recording per employee instead of per tool, or using reports to assess staff. People then stop reporting and you see less.
  • Skipping AI features in existing software. A lot of AI arrives as an update to a package you already use, without new procurement.
  • Treating a general-purpose chat assistant that ranks CVs as an ordinary tool. Recruitment is listed in Annex III, point 4(a); whoever modifies the intended purpose in this way may become the provider of a high-risk AI system (Article 25(1)(c)), with obligations from 2 December 2027.

When do you need legal advice?

  • You want to monitor technically. You are considering network, app or device data to find AI use. Then your organisation as controller will as a rule carry out a DPIA (Article 35 GDPR; many national supervisory authorities list systematic monitoring of employees as requiring one), record the legal basis (Articles 6 and 5(2) GDPR), involve the works council or other employee representatives as your national law requires (in the Netherlands, works council consent under art. 27(1)(l) of the Works Councils Act), and tell staff in advance what you see (Article 13 GDPR).
  • The scan finds AI in decisions about people. Staff use AI in recruitment, appraisal or decisions about customers, pupils or citizens. That may be an Annex III application, with obligations from 2 December 2027: as deployer (Article 26), or even as provider where staff use a general-purpose AI tool for such a purpose themselves (Article 25(1)(c)). If the system was placed on the market or put into service before 2 December 2027, Article 111(2) applies: the obligations apply only after a significant change in its design, and systems intended to be used by public authorities must comply by 2 August 2030 at the latest. The GDPR already applies: a DPIA is often needed, and Article 22 GDPR applies to decisions based solely on automated processing.
  • Personal data is already with an unapproved service. Staff have put data of customers, applicants or patients into a personal account. As controller you assess whether this is a personal data breach; unless it is unlikely to result in a risk to the people concerned, you notify the supervisory authority within 72 hours (Article 33 GDPR), and where the risk is high you also inform the data subjects (Article 34 GDPR).

Frequently asked questions

Can an employer monitor the network to detect shadow AI?

Only under conditions. Network, app and device data are personal data of employees. As controller, your organisation needs a legal basis (Article 6 GDPR), as a rule carries out a DPIA (Article 35 GDPR; systematic employee monitoring appears on many national DPIA lists), involves the works council or other employee representatives where national law requires it, and informs staff in advance (Article 13 GDPR). Reading content and covert monitoring are out.

Does the EU AI Act require an AI inventory or AI register?

The AI Act does not prescribe an internal AI register. But you need to know which AI you use to determine your obligations: AI literacy measures (Article 4, in the wording of Regulation (EU) 2026/1744 since 27 July 2026), transparency (Article 50, applicable since 2 August 2026) and the obligations for high-risk AI systems under Annex III (from 2 December 2027). Registration in the EU database (Article 49) is a different duty that rests mainly on providers.

What if staff have put personal data into a personal AI account?

Then your organisation, as controller, assesses whether this is a personal data breach. Unless it is unlikely to result in a risk to the people concerned, you notify your supervisory authority within 72 hours (Article 33 GDPR), and where the risk is high you also inform the data subjects (Article 34 GDPR). The workbook gives such a tool priority High.

Does my organisation become a provider if staff use a chat assistant to screen applicants?

It may. Whoever uses a general-purpose AI system for an Annex III purpose, such as recruitment and selection (point 4(a)), modifies its intended purpose and may become the provider of a high-risk AI system (Article 25(1)(c)). The obligations for such systems apply from 2 December 2027; the GDPR already applies.

Is AI that recognises employees' emotions allowed?

No. AI that infers the emotions or intentions of employees from biometric data, such as face or voice, is prohibited in the workplace except for medical or safety reasons (Article 5(1)(f)). This prohibition has applied to providers and deployers since 2 February 2025. The workbook closes the privacy gate as soon as such a feature is reported.

How does the scan relate to AI literacy?

Since 27 July 2026, providers and deployers take measures to support the development of AI literacy of their staff and others who operate or use AI systems on their behalf (Article 4); they do not have to guarantee a specific level per person and no certificate is prescribed. The scan shows which tools and tasks exist and what questions staff have, so you can take and record targeted measures per group.

Use and credit

You may use, adapt and share this template freely, including within your organisation, provided the credit 'Source: Praxikon' with the link to this template stays in place.

How to cite this template: Source: Praxikon, Shadow AI checklist and AI system inventory template (free Excel), version 2.0, as of 6 October 2026, https://www.praxikon.com/en/templates/shadow-ai-detection-checklist

This template is a tool, not legal advice for your situation. It reflects the law as of 6 October 2026. Legislation, guidance and supervisory practice may change after that date. Using this template does not guarantee compliance: applying it in your organisation remains your own responsibility.

Praxikon is a trade name of Embed AI · Chamber of Commerce 90283597